← Back to search

CVE-2026-77248

8.6 HIGHpublic exploit available

Published 2026-09-22 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows unauthenticated network callers to read files accessible to the MCP process and upload them to Jira or Confluence, posing a significant security risk.
Exploitability
Exploitation is relatively straightforward, requiring an unauthenticated network caller with access to the streamable HTTP transport.
Blast radius
If exploited, the attacker can read sensitive files and upload malicious content to Jira or Confluence, impacting the confidentiality and integrity of the system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 0.22.0 or later.
auth-bypassfile-readuploadweb

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls back to operator credentials, while upload_attachment accepts an unrestricted file_path. An unauthenticated network caller can read files available to the MCP process, upload them to an attacker-selected Jira issue or Confluence page, and retrieve the contents. The advisory traces the vulnerable input and processing flow through streamable-http, UserTokenMiddleware, upload_attachment, file_path, and _get_fetcher, which identify the affected entry points, controls, and code paths. This issue is fixed in version 0.22.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Weaknesses

CWE-22, CWE-306

Vendors

mcp-atlassian

Products

mcp atlassian

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.